Sr. Security Engineer (Detection)
Solace
—
Jul 22, 2026
—
Jul 24, 2026
What this job asks for AI summary
A hands-on detection and security operations role at a HIPAA-regulated health-tech startup. The primary focus is owning a Datadog SIEM end to end — building and tuning detection rules across cloud, identity, endpoint, and SaaS log sources, reducing alert noise, and serving as a primary incident responder. The role also covers broader security engineering work including cloud hardening, access management, and compliance support, and suits someone comfortable building programs from scratch on a small team.
Mid level · 3+ years · Remote · Full-time
Advertised as Senior, but the requirements read as Mid.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 1,600 people nationally plausibly meet what this posting asks for (information security analysts). range 970–2,900
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The role is titled 'Sr. Security Engineer' but requires only 3–6 years of experience, which aligns with a Mid-level band on a standard career ladder. The advertised seniority reflects the title; the assessed seniority reflects the actual experience gate.
The posting is fully remote but explicitly requires US-based applicants.
No location or CBSA is specified beyond 'United States'; the CBSA fields are left blank accordingly.
Datadog Cloud SIEM is 'strongly preferred' but the JD explicitly accepts deep experience with Splunk, Elastic, Chronicle, Sentinel, or Panther as translating well — these are captured as alternatives on the same requirement.
Okta, Jamf, Snowflake, GitHub, and Vanta appear under the 'Nice to Have' section and are marked preferred accordingly.
Terraform and CI/CD appear under 'Nice to Have' in the context of detection-as-code workflows and are marked preferred.
Tines and Windmill are listed together as SOAR/workflow automation options under 'Nice to Have'; they are captured as a single preferred skill with alternatives.
MITRE ATT&CK is referenced in the required responsibilities section ('Map detection coverage against real-world threats (MITRE ATT&CK)') and is treated as a required competency.
Google Workspace and Okta are both named as identity sources in the required detection scope; Okta also appears under Nice to Have from a security-ops tooling perspective — it is captured once as preferred to reflect the Nice to Have framing, while Google Workspace is marked required as part of the core detection environment.
No compensation figures are disclosed in the posting.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.